Software-Defined Networking (SDN) has emerged as a revolutionary paradigm for network management, offering dynamic control and programmability. However, the open and programmable nature of SDN introduces new challenges, particularly in terms of security. Abnormal traffic does not necessarily mean an attack, but the detection of anomalous patterns and their mitigation in abnormal traffic is a critical aspect in terms of effective protection of SDN entities. In this context, artificial intelligence (AI) techniques have shown great promise in enhancing network security by enabling the identification and mitigation of abnormal traffic patterns. This paper explores the use of AI-based anomaly detection algorithms in SDN environments to detect and mitigate network attacks patterns in abnormal traffic effectively. Initially, specific features were extracted from SDN environment under normal conditions and during DDoS attack scenarios to create a dataset that contains over 1.000.000 records which is a substantial amount for conducting analysis. Dataset features are extracted from the IP header from each packet that passes through the SDN datapath, taking into account that different parameters are important for different protocols. Since different protocols differ in their structure, the entire data set were divided into four sub-datasets according to their specific characteristics (ARP, ICMP, TCP, UDP). As the basis of AI, we employed a variety of machine learning (ML) techniques, including Support Vector Machine (SVM), Decision Tree (DT), Logistic Regression (LR), Random Forest (RF), and Naive Bayes (NB), to train and classify different types of anomalies. The results we have obtained underscore the ability of artificial intelligence to effectively recognize and detect anomalies in abnormal traffic. Our results highlight the effectiveness of artificial intelligence in recognizing and detecting anomalies within abnormal traffic, paving the way for improved SDN security measures. Moving forward, further research will focus on refining AI models, exploring advanced anomaly detection algorithms, and implementing real-time response mechanisms to swiftly mitigate identified threats, ensuring robust and adaptive SDN security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Artificial Intelligence-Based Anomaly Detection Traffic Patterns Associated with the Ddos Attack in Software-Defined Networking

  • Stefan Ž. Biševac,
  • Aleksandar Atanasijević,
  • Aleksandar Jokić,
  • Marko Šarac

摘要

Software-Defined Networking (SDN) has emerged as a revolutionary paradigm for network management, offering dynamic control and programmability. However, the open and programmable nature of SDN introduces new challenges, particularly in terms of security. Abnormal traffic does not necessarily mean an attack, but the detection of anomalous patterns and their mitigation in abnormal traffic is a critical aspect in terms of effective protection of SDN entities. In this context, artificial intelligence (AI) techniques have shown great promise in enhancing network security by enabling the identification and mitigation of abnormal traffic patterns. This paper explores the use of AI-based anomaly detection algorithms in SDN environments to detect and mitigate network attacks patterns in abnormal traffic effectively. Initially, specific features were extracted from SDN environment under normal conditions and during DDoS attack scenarios to create a dataset that contains over 1.000.000 records which is a substantial amount for conducting analysis. Dataset features are extracted from the IP header from each packet that passes through the SDN datapath, taking into account that different parameters are important for different protocols. Since different protocols differ in their structure, the entire data set were divided into four sub-datasets according to their specific characteristics (ARP, ICMP, TCP, UDP). As the basis of AI, we employed a variety of machine learning (ML) techniques, including Support Vector Machine (SVM), Decision Tree (DT), Logistic Regression (LR), Random Forest (RF), and Naive Bayes (NB), to train and classify different types of anomalies. The results we have obtained underscore the ability of artificial intelligence to effectively recognize and detect anomalies in abnormal traffic. Our results highlight the effectiveness of artificial intelligence in recognizing and detecting anomalies within abnormal traffic, paving the way for improved SDN security measures. Moving forward, further research will focus on refining AI models, exploring advanced anomaly detection algorithms, and implementing real-time response mechanisms to swiftly mitigate identified threats, ensuring robust and adaptive SDN security.